mirror of
https://github.com/Sea-Haven-Industries/meal-order-manager.git
synced 2026-09-30 05:23:13 +00:00
* fix(iam): attach per-workload lambda permissions boundary (PLAT-52) * fix(iam): skip boundary delete on weekly-menu role (PLAT-52)
102 lines
3.7 KiB
HCL
102 lines
3.7 KiB
HCL
locals {
|
|
project = "meal-order-manager"
|
|
account_id = "011934824531"
|
|
|
|
# Lambda execution roles under /tf-managed/ carry the per-workload ceiling
|
|
# (PLAT-52). githubdeploy-meal-order-manager-weekly-menu must not.
|
|
boundary_arn = "arn:aws:iam::${local.account_id}:policy/seahaven-lambda-execution-boundary-meal-order-manager"
|
|
|
|
form_bucket_name = "${local.project}-form-${local.account_id}"
|
|
reports_bucket_name = "${local.project}-reports-${local.account_id}"
|
|
artifacts_bucket_name = "${local.project}-artifacts-${local.account_id}"
|
|
|
|
table_name = "${local.project}-orders"
|
|
# Pre-DNS: use the CloudFront domain. After cutover (attach_custom_domain),
|
|
# use the public custom domain.
|
|
form_url = var.attach_custom_domain ? "https://${var.domain_name}" : "https://${aws_cloudfront_distribution.form.domain_name}"
|
|
|
|
ssm_prefix = "/${local.project}"
|
|
slack_channel_param = "${local.ssm_prefix}/slack-channel-id"
|
|
|
|
# google-client-id is created and rotated out-of-band. Terraform reads it
|
|
# (data.tf) but never owns it.
|
|
google_client_id_param = "${local.ssm_prefix}/google-client-id"
|
|
|
|
# shared/slack.py resolves the token by NAME, while the IAM grant is scoped to
|
|
# the ARN in var.slack_bot_secret_arn. Both must refer to the same secret.
|
|
slack_bot_secret_name = "${local.project}/slack-bot-token"
|
|
|
|
ssm_parameter_arn_wildcard = "arn:aws:ssm:${var.aws_region}:${local.account_id}:parameter${local.ssm_prefix}/*"
|
|
|
|
# Directory names under functions/, which build_packages.sh mirrors into
|
|
# terraform/build/functions/.
|
|
function_packages = toset([
|
|
"admin_authorizer",
|
|
"aggregate_orders",
|
|
"close_form",
|
|
"email_report",
|
|
"slack_notifier",
|
|
"submit_order",
|
|
"sync_roster",
|
|
])
|
|
|
|
# SAM Globals.Function.Environment.Variables — every function receives these.
|
|
common_env = {
|
|
TABLE_NAME = local.table_name
|
|
REPORTS_BUCKET = local.reports_bucket_name
|
|
SLACK_CHANNEL_PARAM = local.slack_channel_param
|
|
FORM_URL = local.form_url
|
|
SLACK_BOT_SM_NAME = local.slack_bot_secret_name
|
|
}
|
|
|
|
# HTTP API routes, all integrated with submit-order. `authorizer` selects the
|
|
# authorization mode; `permission_source` is the method/path suffix of the
|
|
# per-route lambda:InvokeFunction grant (path parameters become `*`).
|
|
api_routes = {
|
|
submit_order = {
|
|
route_key = "POST /api/submit-order"
|
|
authorizer = "NONE"
|
|
permission_source = "POST/api/submit-order"
|
|
}
|
|
form_status = {
|
|
route_key = "GET /api/form-status/{week}"
|
|
authorizer = "NONE"
|
|
permission_source = "GET/api/form-status/*"
|
|
}
|
|
roster = {
|
|
route_key = "GET /api/roster"
|
|
authorizer = "NONE"
|
|
permission_source = "GET/api/roster"
|
|
}
|
|
publish_settings = {
|
|
route_key = "GET /api/publish/settings"
|
|
authorizer = "AWS_IAM"
|
|
permission_source = "GET/api/publish/settings"
|
|
}
|
|
publish_menu = {
|
|
route_key = "POST /api/publish/menu"
|
|
authorizer = "AWS_IAM"
|
|
permission_source = "POST/api/publish/menu"
|
|
}
|
|
admin_orders_get = {
|
|
route_key = "GET /api/admin/orders"
|
|
authorizer = "CUSTOM"
|
|
permission_source = "GET/api/admin/orders"
|
|
}
|
|
admin_orders_put = {
|
|
route_key = "PUT /api/admin/orders"
|
|
authorizer = "CUSTOM"
|
|
permission_source = "PUT/api/admin/orders"
|
|
}
|
|
admin_orders_delete = {
|
|
route_key = "DELETE /api/admin/orders"
|
|
authorizer = "CUSTOM"
|
|
permission_source = "DELETE/api/admin/orders"
|
|
}
|
|
admin_summary_pdf = {
|
|
route_key = "GET /api/admin/summary-pdf"
|
|
authorizer = "CUSTOM"
|
|
permission_source = "GET/api/admin/summary-pdf"
|
|
}
|
|
}
|
|
}
|